First published: Tue Apr 29 2025(Updated: )
A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape.
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <138 | 138 |
Firefox ESR | <115.23 | 115.23 |
Mozilla Thunderbird | <128.10 | 128.10 |
Firefox ESR | <128.10 | 128.10 |
Firefox | <138 | 138 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of MFSA-RESERVE-2025-1958350 is high due to its potential for a sandbox escape.
To fix MFSA-RESERVE-2025-1958350, upgrade to the latest version of affected Mozilla products.
Versions prior to Thunderbird 138, Firefox 138, and their ESR equivalents are affected by MFSA-RESERVE-2025-1958350.
The affected products include Mozilla Thunderbird, Firefox, and their ESR versions.
MFSA-RESERVE-2025-1958350 is caused by improper handling of javascript: URIs leading to process isolation issues.